URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: goldcake.co.id
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2021-01-26 16:49:04 UTC
Total malware sites :1
A record(s) observed :4

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-27 11:28:55 125.253.93.186cs51.koneksiaman.netNot listedAS59210 PHOENIXNAP-AS-SG1- SGyes
2025-05-03 10:11:44 103.253.215.19Not listedAS58487 CRI-AS-AP- IDno
2021-11-07 09:46:24 131.153.99.18cs30.koneksiaman.netNot listedAS59210 PHOENIXNAP-AS-SG1- SGno
2021-01-26 16:49:11 63.251.125.5Not listedAS14636 INTERNAP-BLK4- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-01-26 16:49:12https://goldcake.co.id/pn892f.zipOfflineDridex ext payload Myrtus0x0

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-11-09 12:39:572d0066273a65fd326d459caf26be43c274d7b10a15e3bdc4488a79e8732626c8dll  
2021-11-09 12:19:5467a0286d4680968a0e0cc0c22c996fdc1ef21fc0898172d524d36a9a859a8fb1dll  
2021-01-26 16:49:1026bf46b79aeb7775dbf7ccef58f5becb631ac14591ec9e1cdad6962600db5bc6dllDridex